MAL-2025-1854

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/instacart-api-client/MAL-2025-1854.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-1854
Published
2025-03-03T13:29:37Z
Modified
2025-03-03T13:29:37Z
Summary
Malicious code in instacart-api-client (npm)
Details

-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "999.9.9"
            ],
            "id": "RLMA-2025-00902",
            "source": "reversing-labs",
            "sha256": "4b68fab26858c054ff936a7a51f835bf7ec2a2a7e6ee3b517b6efef81cf683dd",
            "modified_time": "2025-03-03T13:29:37Z",
            "import_time": "2025-03-03T15:06:47.779877606Z"
        }
    ]
}
References
Credits

Affected packages

npm / instacart-api-client

Package

Name
instacart-api-client
View open source insights on deps.dev
Purl
pkg:npm/instacart-api-client

Affected ranges

Affected versions

999.*

999.9.9